Signed-off-by: Stephen Gran <steve@lobefin.net>
}
@def &TCP_UDP_SERVICE($port) = {
- proto tcp mod state state (NEW) dport $port ACCEPT;
- proto udp mod state state (NEW) dport $port ACCEPT;
+ proto (tcp udp) mod state state (NEW) dport $port ACCEPT;
}
@def $HOST_MUNIN = (192.25.206.33);
}
@include 'dsa.d/';
+
+domain (ip ip6) {
+ chain INPUT {
+ jump log_or_drop;
+ }
+}
notify => Exec["ferm restart"];
}
- ferm::rule { "dsa-drop":
- domain => "(ip ip6)",
- description => "Drop everything else",
- prio => "99",
- rule => "jump log_or_drop"
- }
-
-
exec { "ferm restart":
command => "/etc/init.d/ferm restart",
refreshonly => true,